PT-2025-52829 · Unknown · Orangescrum

Hubert Wojciechowski

·

Published

2025-12-23

·

Updated

2025-12-23

·

CVE-2021-47720

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Orangescrum version 1.8.0
Description Orangescrum version 1.8.0 has an authenticated SQL injection issue. Authorized users can manipulate database queries through vulnerable parameters. Specifically, attackers can inject malicious SQL code into parameters such as old project id, project id, uuid, and uniqid. This could allow for the extraction or modification of database information.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-47720

Affected Products

Orangescrum